Support

Akeeba Backup for Joomla!

#30394 ChaseBank-A message from AVG when opening Akeeba for Joomla

Posted in ‘Akeeba Backup for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Akeeba Backup version
n/a

Latest post by janbigw on Sunday, 28 October 2018 11:57 CDT

janbigw
Please look at the bottom of this page (under Support Policy Summary) for our support policy summary, containing important information regarding our working hours and our support policy. Thank you!

EXTREMELY IMPORTANT: Please attach a ZIP file containing your Akeeba Backup log file in order for us to help you with any backup or restoration issue. If the file is over 2Mb, please upload it on your server and post a link to it.

Description of my issue:

All of a sudden today my AVG Internet Security PC utility is blocking Akeeba backup from opening in Joomla back end, popping up a message that it has detected an infection with HTML:ChaseBank-A [phish]. It only happens when clicking on Components->Akeeba Backup from my admin menu bar. No other components are an issue.

It is happening in several sites with different Joomla and PHP 7 & 5.6 versions, but all Akeeba 6.2.1. Different site templates. Four different web hosts (so far). Earlier today I was working with Akeeba profiles in one of the sites with no issue at all.

I tried uninstalling Akeeba from one system, then erasing all files associated with it, and reinstalling from a fresh download. Same thing.

Have you had such reports from other users?

janbigw
Update:

As mysteriously as that AVG blockage started today, it later stopped. Now no problem accessing Akeeba.

Weird stuff.

nicholas
Akeeba Staff
Manager
This was a false positive. Both AVG and Avast were misidentifying legitimate code for malware. This happened because of the way they are scanning for PHP and JavaScript malware, using pattern matching. Unfortunately they ended up marking legitimate core PHP and JavaScript functions as malware indicators. They fixed it soon afterwards.

I strongly recommend ditching third party antivirus for Windows Defender which comes preinstalled with Windows 10. It's actually a very reliable antivirus with the benefit of being fed with real world data from hundreds of millions of devices (and, of course, VirtusTotal). The update cycle is much shorter, meaning that false positives are fixed in a matter of hours, not days. I know that Windows Defender has a branding issue because before Windows 10 was released it was the name of a rather poor firewall. I don't know why Microsoft reused a name with bad connotations for a stellar product but, well, they did.

Since this is the third time I am replying to this question in 12 hours and given that 8 of them I was asleep, would you mind if I make this ticket public so other people can see that there is actually not a problem?

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

janbigw
Thanks for the explanation.

I can't immediately see how to change this to a public ticket. If you can you have my permission.

Either way you can close it if there is no more.

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!